PULSE the living trend engine
▲ Peaking Technology

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft has released a massive security update addressing 421 CVEs, including a Windows driver zero-day currently being exploited by attackers.

1sources
1articles
0velocity
+0%since first seen
1h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

Microsoft has released its August 2026 Patch Tuesday updates to address a significant volume of security vulnerabilities across its ecosystem. According to reporting from SecurityWeek, the company has fixed 421 Common Vulnerabilities and Exposures (CVEs) in this latest cycle. Among these fixes is a critical patch for a Windows driver zero-day vulnerability. This specific flaw is particularly urgent because it is currently under active attack, meaning malicious actors are leveraging the exploit in the wild before the patch was available to the general public. Coverage from SecurityWeek emphasizes the scale of this update, noting the sheer number of CVEs being resolved in a single release.

The report highlights that the patched zero-day vulnerability specifically affects a Windows driver, which often grants attackers deep access to system kernels or hardware. By identifying and patching these 421 vulnerabilities, Microsoft aims to close various entry points that could be used for unauthorized system access or data breaches. The focus remains on the exploited driver, as active exploitation increases the immediate risk to unpatched systems. This event is part of the recurring Patch Tuesday cycle, a scheduled monthly release of security and quality updates for Microsoft products. The presence of a zero-day exploit adds a layer of criticality to this specific window, as these vulnerabilities are discovered by attackers before the software vendor is aware of them or has a fix ready.

The breadth of the update, covering over 400 distinct vulnerabilities, underscores the complexity of maintaining security across the vast Windows architecture and the constant evolution of threats targeting system drivers. Following this release, the immediate priority for system administrators and users is the deployment of the August 2026 patches to mitigate the risk of the active zero-day exploit. Future developments will depend on whether other vulnerabilities among the 421 CVEs are found to be exploited in the wild. Organizations are expected to monitor for any further guidance from Microsoft regarding the specific driver affected. As the industry responds to these updates, further technical details regarding the nature of the exploit may emerge from security researchers analyzing the patches.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 1h ago.

Quick answers

How many vulnerabilities did Microsoft fix in August 2026?

Microsoft fixed 421 CVEs during the August 2026 Patch Tuesday.

Is there a zero-day vulnerability in this update?

Yes, there is one exploited zero-day vulnerability affecting a Windows driver.

Which outlet reported on these security updates?

SecurityWeek reported on the August 2026 Patch Tuesday fixes.

Coverage (1)

Topics

Related trends

▲ Peaking Technology

Microsoft Plugs Nearly 400 Security Holes

Microsoft addresses nearly 400 security vulnerabilities in its August 2026 Patch Tuesday update, including an active zero-day exploit.

1 sources 1 articles v 1 2h ago